Skip to content
calico-policy-controller.yml.j2 1.88 KiB
Newer Older
apiVersion: extensions/v1beta1
kind: ReplicaSet
metadata:
  name: calico-policy-controller
  namespace: {{ system_namespace }}
  labels:
    k8s-app: calico-policy
    kubernetes.io/cluster-service: "true"
spec:
  replicas: 1
  selector:
    matchLabels:
      kubernetes.io/cluster-service: "true"
      k8s-app: calico-policy
  template:
    metadata:
      name: calico-policy-controller
      namespace: {{system_namespace}}
      labels:
        kubernetes.io/cluster-service: "true"
        k8s-app: calico-policy
    spec:
      hostNetwork: true
      containers:
        - name: calico-policy-controller
          image: {{ calico_policy_image_repo }}:{{ calico_policy_image_tag }}
          imagePullPolicy: {{ k8s_image_pull_policy }}
              value: "{{ etcd_access_endpoint }}"
Matthew Mosesohn's avatar
Matthew Mosesohn committed
            - name: ETCD_CA_CERT_FILE
              value: "{{ etcd_cert_dir }}/ca.pem"
            - name: ETCD_CERT_FILE
              value: "{{ etcd_cert_dir }}/node.pem"
            - name: ETCD_KEY_FILE
              value: "{{ etcd_cert_dir }}/node-key.pem"
            # Location of the Kubernetes API - this shouldn't need to be
            # changed so long as it is used in conjunction with
            # CONFIGURE_ETC_HOSTS="true".
            - name: K8S_API
              value: "https://kubernetes.default:443"
            # Configure /etc/hosts within the container to resolve
            # the kubernetes.default Service to the correct clusterIP
            # using the environment provided by the kubelet.
            # This removes the need for KubeDNS to resolve the Service.
            - name: CONFIGURE_ETC_HOSTS
              value: "true"
Aleksandr Didenko's avatar
Aleksandr Didenko committed
          volumeMounts:
          - mountPath: {{ etcd_cert_dir }}
            name: etcd-certs
            readOnly: true
      volumes:
      - hostPath:
          path: {{ etcd_cert_dir }}
        name: etcd-certs